1200KM / detection
T1547.010 Port Monitors — Detection Rules
Detection workspace for T1547.010 Port Monitors: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
- Add Port Monitor Persistence in Registry · test · medium · {"category":"registry_set","product":"windows"}
- Bypass UAC Using Event Viewer · test · high · {"category":"registry_set","product":"windows"}
- Default RDP Port Changed to Non Standard Port · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0204 Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)
AN0580 Analytic 0580
Detects suspicious registry modifications under `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\*\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\Windows\System32` not tied to known patches or installations.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1547.010 simulation workspace
- File Creation · DC0039
- Module Load · DC0016
- OS API Execution · DC0021
- Process Creation · DC0032
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.